Live data from Hacker News

Intel patches new ME vulnerabilities

blog.ptsecurity.com

271–280 of 337 posts

Re: Intel patches new ME vulnerabilities

#271

Just a note that if you want to avoid Intel's disastrous Management Engine, there are companies you can support that disable it. Purism[0] sell nice MBP-style, Debian-based laptops with modern Intel processors with the NSA's 'High Assurance Platform' bit set, and as much of the ME code removed as possible. It still runs briefly at boot, but this is the most-disabled you can currently get on any i3/i5/i7 processor[1].…

At that point you should just buy AMD, if only to not support a company like Intel with such a bad security track record.

Re: Intel patches new ME vulnerabilities

#272

Earlier quoted context omitted.

I've never seen this 2 year thing in Europe. There are plenty of companies that stick to their servers for over 5 years. Some servers stay there even for more than a decade because they deliver a service using software that is no longer developed or supported, and there's no replacement for it in the company. So they keep them there, chugging along. But with x86 being basically commodity and virtualization being used…

I consult in verticals where uptime really matters. It's not unusual though, but yes, I know that companies do this. They usually don't care about insurance/hardware SLA though. Old hardware needs to be emulated.

Oh I'm sure some companies do it. Whatever it is you can be certain someone is doing it :). But it's nowhere near being a rule in Europe.

And TBH replacing servers after 2 years because you're worried about uptime feels like a horrible overreaction and self harming at the same time. Servers that are meant to provide 99.999% uptime (so 5 nines or above, or maximum 6min downtime per year) are built to run for far longer than 2 years. And they must be supported by the manufacturer of the system and the manufacturer of every sub-component for longer than that.

So unless I'm missing something I really can't see the benefit of such upgrade cycles.

Re: Intel patches new ME vulnerabilities

#273

Earlier quoted context omitted.

Finally? That ME thing should be nowhere near private and confidential data. There's constantly bugs being found in it [1][2]. Honestly if you are a large company, organisation, government, etc and you are using Intel or AMD products, then you are being very irresponsible. There is no excuse, enough information is out there that even a non-technical CTO should know better. 1. https://www.wired.com/story/intel-managem…

There is quite literally no viable alternative to x86 for 95% (more like 99.9%, but I am being generous) of the server and workstation market. Pretending like there is and anyone choosing x86 is irresponsible is just being a smug fool.

Huh? This has nothing to do with x86.

Re: Intel patches new ME vulnerabilities

#274

Earlier quoted context omitted.

One thing the PSP doesn't have is AMT style remote management. AMD has their own kind of management system available on some machines (DASH, using "smart" NICs like Broadcom), but the PSP isn't even involved when DASH is available and in use, as far as I know. However, on my Intel machine with AMT, there's a network port opened by the ME itself (TCP/16992). It can use the same IP as the main OS, or a different IP ent…

You know the shame of ME is that the concept and intended use isn't terrible and the engineering behind it is rather cool. It is however unfortunate how poorly Intel implemented it and essentially forced it onto personal systems that have no need for it to begin with.

It just should not be there unless requested by the customer. Period.

Re: Intel patches new ME vulnerabilities

#275

Just a note that if you want to avoid Intel's disastrous Management Engine, there are companies you can support that disable it. Purism[0] sell nice MBP-style, Debian-based laptops with modern Intel processors with the NSA's 'High Assurance Platform' bit set, and as much of the ME code removed as possible. It still runs briefly at boot, but this is the most-disabled you can currently get on any i3/i5/i7 processor[1].…

This is a great reference - but I confess to being mightily disappointed at the state of the industry with regards to this issue.

Sadly, it seems like its going to need a major incident before people start to pay attention. I can't believe I'm actually rooting for the black-hats to do something so terrible, it wakes us all up.

Re: Intel patches new ME vulnerabilities

#276

Earlier quoted context omitted.

I consult in verticals where uptime really matters. It's not unusual though, but yes, I know that companies do this. They usually don't care about insurance/hardware SLA though. Old hardware needs to be emulated.

Oh I'm sure some companies do it. Whatever it is you can be certain someone is doing it :). But it's nowhere near being a rule in Europe. And TBH replacing servers after 2 years because you're worried about uptime feels like a horrible overreaction and self harming at the same time. Servers that are meant to provide 99.999% uptime (so 5 nines or above, or maximum 6min downtime per year) are built to run for far longe…

The general warranty is always 2 years in the Czech Republic.

Re: Intel patches new ME vulnerabilities

#277
post #188

Earlier quoted context omitted.

For what it's worth and graphics on Linux are working great with amdgpu. Their efforts to develop and support open source mainline graphics has really finally paid off. Support is usually mainlined before hardware release now. I don't think "just works" integrated graphics are an issue for either company (Intel/AMD) in general on the Linux front. That said the amdgpu driver is still relatively new and major changes a…

Except for those that happen to own an older card that used to work perfectly fine on the former AMD driver. Case in point, the ATI Radeon HD 6310 that came on EEE PC models, the video hardware acceleration no longer works as it used to be. Sure, I can probably hack the older driver into newer Ubuntu releases or track down someone that has already done it, but that is exactly what I don't want to spend my time doing…

FWIW, it’s a completely different architecture. GCN has support all the way down to 1.0. The graphics card in your EEE PC is upgradable, if you’re feeling adventurous[1].

[1] https://www.ifixit.com/Guide/Asus+Eee+PC+1008ha+Graphics+Car...

Re: Intel patches new ME vulnerabilities

#279

Earlier quoted context omitted.

It’s difficult to see the reason for including this on by default other than some conspiracy involving government agencies and a lot of money.

There was a submission on the weekend which posited that ME was made mandatory because of lobbying from the content industry to implement copy protection that the OS cannot tamper with (HDCP etc.).

So are they paying Intel to do that? How much? Why would Intel agree to that? Otherwise seems like a convenient cover for the aforementioned conspiracy theory…

Re: Intel patches new ME vulnerabilities

#280
post #63

Do we really need remote code execution on the bios level? Is this a case of 'we can, but should we?'

Think about managing tens of thousands of server in a datacenter. An ability to do everything you can do form a local console (and preferably more), without physical access or a KV switch, is very important. Remotely managing a corporate desktop or laptop, e.g. fixing an OS-level problem remotely, may also be important. OTOH I'd prefer this functionality clearly delineated, usinf strong encryption, and with an explic…

How many people honestly use Intels ME for managing their servers (or large desktop installations)?

I have yet to see or even hear someone defend the ME on the grounds that they use it daily. With a few SPARC servers as the exception, we have a 100+ Intel based servers and we don't feel the need for using Intels Management Engine.

Post reply on HN